Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
Luxembourg's Law of 1 August 2018 organising the National Commission for Data Protection (CNPD) and supplements the GDPR with national provisions. The Commission Nationale pour la Protection des Données (CNPD) oversees enforcement. Luxembourg is significant as the EU establishment of many major tech companies (Amazon, PayPal, Skype). The law includes provisions for the age of digital consent (16 years), processing by the public sector, research derogations, and employee data. CNPD has jurisdiction over major data controllers established in Luxembourg.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Accountability
| Code | Title |
|---|---|
| LU-DPA-Art-69 | Codes of Conduct and Certification |
| LU-DPA-RoPA | Records of Processing Activities |
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2-4) |
Chapter II - National Data Protection Commission (CNPD)
| Code | Title |
|---|---|
| Art. 11 | Technical Documentation |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
Chapter III - Processing Conditions
| Code | Title |
|---|---|
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 25 | Criminal Penalties |
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 30 | Privacy Policy |
Chapter IV - Specific Processing Situations
| Code | Title |
|---|---|
| Art. 36 | Right to Correction or Deletion |
| Art. 38 | Processing in Employment Context |
| Art. 40 | Establishment and Composition |
| Art. 42 | Processing for Archiving Purposes |
Chapter V - Remedies and Sanctions
| Code | Title |
|---|---|
| Art. 44 | Right to Effective Judicial Remedy |
| Art. 46 | Administrative Fines |
| Art. 48 | Criminal Penalties |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
Chapter VI - Transitional and Final Provisions
| Code | Title |
|---|---|
| Art. 55 | Obligations for Providers of General-Purpose AI Models with Systemic Risk |
| Art. 57 | Transitional Provisions |
| Art. 59 | Entry into Force |
Derogations
| Code | Title |
|---|---|
| LU-DPA-Art-52 | Processing of Personal Data for Journalistic Purposes |
Employment
| Code | Title |
|---|---|
| LU-DPA-Art-63 | Surveillance in the Workplace |
Enforcement
| Code | Title |
|---|---|
| LU-DPA-Art-43 | Limitation on Administrative Fines for Public Sector |
| LU-DPA-Art-9 | CNPD Investigatory and Corrective Powers |
Governance
| Code | Title |
|---|---|
| LU-DPA-Art-50 | Designation of the Data Protection Officer |
Incident Response
| Code | Title |
|---|---|
| LU-DPA-Breach | Personal Data Breach Notification |
Marketing
| Code | Title |
|---|---|
| LU-DPA-Marketing | Electronic Marketing and Cookies |
Research
| Code | Title |
|---|---|
| LU-DPA-Art-65 | Processing for Scientific, Historical, and Statistical Research |
Rights
| Code | Title |
|---|---|
| LU-DPA-Art-72 | Restrictions on Data Subject Rights for National Interests |
Risk
| Code | Title |
|---|---|
| LU-DPA-DPIA | Data Protection Impact Assessments |
Scope
| Code | Title |
|---|---|
| LU-DPA-Art-1 | Scope and Implementation of GDPR |
Sectoral
| Code | Title |
|---|---|
| LU-DPA-Sector | Sectoral Rules for Financial Services and CSSF Supervision |
Special Processing
| Code | Title |
|---|---|
| LU-DPA-Art-67 | Whistleblowing and Internal Reporting Channels |
Supervisory Authority
| Code | Title |
|---|---|
| LU-DPA-Art-4 | CNPD Composition and Independence |
Transfers
| Code | Title |
|---|---|
| LU-DPA-Transfers | International Data Transfers |
Transparency
| Code | Title |
|---|---|
| LU-DPA-Multilingual | Multilingual Information and Communication Obligations |
Your Compliance Coverage
If you comply with Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation), you already cover:
EU AI Act
31%
16 controls mapped
Compare →Ethiopia Personal Data Protection Proclamation (No. 1321/2024)
31%
16 controls mapped
Compare →Digital Services Act (DSA) - Regulation (EU) 2022/2065
31%
16 controls mapped
Compare →+ 579 more: Serbia Law on Personal Data Protection (2018) (31%), Montenegro Law on Personal Data Protection (2023) (31%)
See all 582 mapped frameworks ↓Maps to 582 other frameworks
Frequently Asked Questions
What is Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)?
Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) is a compliance framework from Luxembourg with 22 domains and 53 controls. Luxembourg's Law of 1 August 2018 organising the National Commission for Data Protection (CNPD) and supplements the GDPR with national provisions. The Commission Nationale pour la Protection des Données (CNPD) oversees enforcement. Luxembourg is significant as the EU establishment of many major tech companies (Amazon, PayPal, Skype). The law includes provisions for the age of digital consent (16 years), processing by the public sector, research derogations, and employee data. CNPD has jurisdiction over major data controllers established in Luxembourg. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) have?
Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) has 53 controls organised across 22 domains. The largest domains are Chapter I - General Provisions (15 controls), Chapter II - National Data Protection Commission (CNPD) (5 controls), Chapter III - Processing Conditions (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) map to?
Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) maps to 582 other compliance frameworks. The top mapping partners are EU AI Act (31% coverage), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (31% coverage), Digital Services Act (DSA) - Regulation (EU) 2022/2065 (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) compliance?
Start your Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required